Is ad speedup skip video ads safe?

High risk

Ad Speedup is high risk. On install and each ad-skip use, AdSpeedUp makes a permanent ID and sends it with a session ID and event name to Google Analytics. Synced storage carries it across your devices. Capture confirmed five POSTs sharing the same client_id.…

75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Persistent UUID synced across devices, reported to Google Analytics

On install and each ad-skip use, AdSpeedUp makes a permanent ID and sends it with a session ID and event name to Google Analytics.

Synced storage carries it across your devices.

Capture confirmed five POSTs sharing the same client_id.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install the extension, or use any ad-skip feature.

The extension did this

The extension sends your permanent browser ID and a session ID to Google Analytics.

The ID is stored in chrome.storage.sync, which means it follows your Google account across devices.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.google-analytics.com/mp/collect?measurement_id=G-X6Q0B1MD64&api_secret=<redacted>
5 POST requests observed during dynamic analysis. client_id value consistent across all requests (same UUID).
Headers
Content-Typeapplication/json
Body
{
  "client_id": "caa46341-f75d-4333-9d8b-c29b4111b3d8",
  "events": [
    {
      "name": "extension_error",
      "params": {
        "session_id": "1745574612347",
        "engagement_time_msec": 100,
        "reason": ""
      }
    }
  ]
}
03EvidenceFIELD TABLE
What the extension sends to Google Analytics on each event:
FieldValueWhy it matters
Your permanent browser ID
caa46341-f75d-4333-9d8b-c29b4111b3d8A random UUID from first install, stored in your synced Google account. The same ID appears on every device using this extension.
Your current session ID
1745574612347A timestamp-derived ID reset every 30 minutes of inactivity. Links your actions within a browsing session.
What you did
ads_skippedThe name of the feature you used or the lifecycle event that fired.
Ad skip count
3For ads_skipped events, the number of ads skipped in the action.
04EvidenceCODE COMPARE
The code that does this

The tracking class from background.js (shipped minified, deobfuscated below):

What it actually does
getOrCreateClientId — reads or creates a permanent UUID in synced storage
async getOrCreateClientId() {
  let { clientId } = await chrome.storage.sync.get('clientId');
  if (!clientId) {
    clientId = self.crypto.randomUUID();
    await chrome.storage.sync.set({ clientId });
  }
  return clientId;
}
fireEvent — POSTs lifecycle and feature events to Google Analytics
async fireEvent(eventName, params = {}) {
  if (!params.session_id) params.session_id = await this.getOrCreateSessionId();
  if (!params.engagement_time_msec) params.engagement_time_msec = 100;
  try {
    const endpoint = 'https://www.google-analytics.com/mp/collect';
    await fetch(
      `${endpoint}?measurement_id=G-X6Q0B1MD64&api_secret=<redacted>`,
      {
        method: 'POST',
        body: JSON.stringify({
          client_id: await this.getOrCreateClientId(),
          events: [{ name: eventName, params: { session_id: await this.getOrCreateSessionId(), engagement_time_msec: 100, ...params } }]
        })
      }
    );
  } catch {}
}
05EvidenceTHIRD PARTY LIST
Where the data is sent:
  • www.google-analytics.com

    Google Analytics Measurement Protocol endpoint. Receives client_id, session_id, event names, tied to GA property G-X6Q0B1MD64 under the developer's account.

Updated 21 September 2026pcjlckhhhmlefmobnnoolakplfppdchi